<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Marinos/Ashish, Thanks in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise1-3-wireless-configuration/m-p/2700977#M55403</link>
    <description>&lt;P&gt;Hello&amp;nbsp;Marinos/Ashish,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your advise,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understood and configured a single VLAN for domain users and they are able to connect if system is in domain, Guest user will connect to another ssid.&amp;nbsp;Client requirement is only for authentication because of having base license only. But I have some few question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I have configured one wireless authorization policy for domain users but users are authenticating another default&amp;nbsp;&lt;STRONG&gt;Basic_Authenticated_Access &lt;/STRONG&gt;policy in which Permission is permit access. And users are getting the same VLAN IP address&amp;nbsp;which I have mapped in wlc against&amp;nbsp;ssid. &amp;nbsp;There is no VLAN tagging happening but only domain user's are authenticating. So it means only one VLAN required for authentication only or do we require separate&amp;nbsp;preauth vlan.&lt;/P&gt;&lt;P&gt;2. Do we require to configure dynamic ACL in WLC, if yes then what would it be.&lt;/P&gt;&lt;P&gt;3. Can we restrict only one domain user id will get connected at a time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards:&lt;/P&gt;&lt;P&gt;Kamlesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 May 2015 07:34:51 GMT</pubDate>
    <dc:creator>kamlenegi</dc:creator>
    <dc:date>2015-05-27T07:34:51Z</dc:date>
    <item>
      <title>ISE1.3 Wireless configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-3-wireless-configuration/m-p/2700974#M55400</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are implementing ISE 1.3 for wireless users, please advise where to map quarantine vlan when user first connect to ssid. If user is domain then get the actual vlan ip address if not then get guest vlan IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-3-wireless-configuration/m-p/2700974#M55400</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2019-03-11T05:45:20Z</dc:date>
    </item>
    <item>
      <title>Hello Kamlesh,In a wireless</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-3-wireless-configuration/m-p/2700975#M55401</link>
      <description>&lt;P&gt;Hello Kamlesh,&lt;/P&gt;&lt;P&gt;In a wireless environment, authentication must be done before anything else (using dot1x). So you don't need a "quarantine" vlan. If user is authenticated (using AD credentials or certificate) then he has access to the "actual" vlan.&lt;/P&gt;&lt;P&gt;You cannot use a fallback vlan if authentication fails.&lt;/P&gt;&lt;P&gt;Please explain me what you have in your mind.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Alexandros.&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2015 13:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-3-wireless-configuration/m-p/2700975#M55401</guid>
      <dc:creator>Alexandros Marinos</dc:creator>
      <dc:date>2015-05-26T13:34:41Z</dc:date>
    </item>
    <item>
      <title>Agreed.Authentication is best</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-3-wireless-configuration/m-p/2700976#M55402</link>
      <description>&lt;P&gt;Agreed.&lt;/P&gt;&lt;P&gt;Authentication is best option to fullfill the requirement in your case.&lt;/P&gt;&lt;P&gt;Generally for the Guest users we can use authentication or it can bypass the phase, May be separate SSID's will be solution for your case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards:&lt;/P&gt;&lt;P&gt;Ashish Arora&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2015 17:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-3-wireless-configuration/m-p/2700976#M55402</guid>
      <dc:creator>Ashish Arora</dc:creator>
      <dc:date>2015-05-26T17:49:07Z</dc:date>
    </item>
    <item>
      <title>Hello Marinos/Ashish, Thanks</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-3-wireless-configuration/m-p/2700977#M55403</link>
      <description>&lt;P&gt;Hello&amp;nbsp;Marinos/Ashish,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your advise,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understood and configured a single VLAN for domain users and they are able to connect if system is in domain, Guest user will connect to another ssid.&amp;nbsp;Client requirement is only for authentication because of having base license only. But I have some few question:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I have configured one wireless authorization policy for domain users but users are authenticating another default&amp;nbsp;&lt;STRONG&gt;Basic_Authenticated_Access &lt;/STRONG&gt;policy in which Permission is permit access. And users are getting the same VLAN IP address&amp;nbsp;which I have mapped in wlc against&amp;nbsp;ssid. &amp;nbsp;There is no VLAN tagging happening but only domain user's are authenticating. So it means only one VLAN required for authentication only or do we require separate&amp;nbsp;preauth vlan.&lt;/P&gt;&lt;P&gt;2. Do we require to configure dynamic ACL in WLC, if yes then what would it be.&lt;/P&gt;&lt;P&gt;3. Can we restrict only one domain user id will get connected at a time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards:&lt;/P&gt;&lt;P&gt;Kamlesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2015 07:34:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-3-wireless-configuration/m-p/2700977#M55403</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2015-05-27T07:34:51Z</dc:date>
    </item>
  </channel>
</rss>

